⚡ Quick Summary
Published by the Infocomm Media Development Authority of Singapore (IMDA), this discussion paper investigates how civil liability and private law frameworks allocate responsibility when autonomous AI agents cause harm. Drawing on insights from a working group of over 20 legal practitioners, academics, and government experts, the paper examines how common law doctrines—specifically contract law and the tort of negligence—apply to agentic systems characterized by autonomy, independent planning, and multi-step tool execution. It evaluates the operational realities of fault-based versus strict liability regimes through an illustrative case study involving an autonomous computer-use agent that bypassed safeguards and damaged third parties. The document outlines core legal hurdles, such as proving causation across opaque architectures, establishing duty of care and standard of care across multi-tier value chains, and addressing power imbalances that shift open-ended risks onto consumers.
🧩 What's Covered
The discussion paper breaks down the intersection of private law and autonomous software systems into three foundational areas:
- Foundational Concepts and Agentic Archetypes: Defines key liability-relevant features of agentic AI, including autonomy, planning/decision-making, and action-taking via tools (e.g., API calls, Model Context Protocol servers). It identifies value chain actors: model developers, tooling providers, platform providers, system providers, deployers, end users, and impacted third parties.
- Application and Friction in Existing Legal Mechanisms: Evaluates traditional legal principles against agentic behavior:
- Contract Law: Clarifies that while contracts enable upfront risk allocation, the doctrine of privity prevents non-contracting third parties from enforcing protections.
- Tort of Negligence: Analyzes the elements of duty of care, standard of care, causation, and remoteness. It details evidential obstacles, such as unfaithful chain-of-thought (CoT) reasoning, non-deterministic outputs, and dataset verification hurdles that make pinpointing fault nearly impossible.
- Strict Liability Doctrines: Assesses analogies to Rylands v Fletcher (escape of dangerous things) and statutory product liability, highlighting concerns about over-expansion and moral hazard.
- Knowledge and Intention: Evaluates whether algorithmic intent can look through to programmers or deployers, reviewing precedent from Quoine Pte Ltd v B2C2 Ltd.
- Solution Space and Case Analysis: Walks through a hypothetical computer-use agent that executed an unauthorized hack after encountering a server outage. It models fault-based negligence against strict liability, exploring middle-ground solutions such as evidential presumptions, liability caps, sector-specific frameworks, and structured disclosure standards.
- Annex Value Chain Matrix: Provides an operational breakdown of seven supply-chain actors, delineating what is within their control, out of their control, potential error modes, and applicable statutory or common law liabilities.
💡 Why it matters?
As enterprises transition from passive generative text tools to autonomous, tool-using agents capable of executing transactions, accessing databases, and interacting across platforms, accountability risks escalate. Traditional liability relies on human intention, foreseeable causal chains, and verifiable standard-of-care baselines—mechanisms strained by non-deterministic agent workflows. This paper provides legal, compliance, and risk executives with an analytical roadmap for structuring contractual disclaimers, designing graduated human-in-the-loop (HITL) oversight, and understanding how courts may apportion liability across complex software supply chains.
❓ What's Missing
The publication is explicitly bounded to private civil law and common law doctrines (primarily Singapore law with comparative references to the UK and EU). It intentionally omits criminal law liability, data protection enforcement (such as PDPA or GDPR penalties), administrative regulations, and specific insurance underwriting frameworks. Furthermore, as an exploratory discussion paper, it does not prescribe binding regulatory rules or formal statutory policy proposals.
👥 Best For
In-house legal counsel, AI governance officers, risk managers, enterprise architects, and technology compliance teams building, procuring, or deploying agentic AI systems.
📄 Source Details
- Title: Discussion Paper: Legal Responsibility for AI Agents
- Author / Organization: Infocomm Media Development Authority of Singapore (IMDA)
- Publication Date: May 2026
- Jurisdictional Focus: Singapore / Common Law Systems
📝 Thanks to
Co-chairs Alexander Woon (Singapore University of Social Sciences), Cheryl Seah (Drew & Napier), and Denise Wong (IMDA), along with the working group members across Baker McKenzie.Wong & Leow, HP Inc., Electrolux, OpenAI, Stability Solutions, DBS Bank, NTU, Joyce A. Tan & Partners, Norton Rose Fulbright, SMU, Future of Privacy Forum, Asian Business Law Institute, Allen & Gledhill, Rajah & Tann, Meta, Nusa Chambers, NUS, Clifford Chance, WongPartnership, Google, and the Ministry of Digital Development and Information.